Sample viewer

vx.netlux.org/Virus.DOS.Michael.1458

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:45.54700636Z 72 PC: 12ac6 | Allocate memory
2018-12-17T23:01:45.549660768Z 74 PC: 12add | Reallocate memory
2018-12-17T23:01:45.553723641Z 88 PC: 12ae2 | case 0xGet or set allocation strateg:
2018-12-17T23:01:45.557588593Z 88 PC: 12aec | case 0xGet or set allocation strateg:
2018-12-17T23:01:45.559250877Z 72 PC: 12af3 | Allocate memory
2018-12-17T23:01:45.561895807Z 88 PC: 12afc | case 0xGet or set allocation strateg:
2018-12-17T23:01:45.563279627Z 53 PC: 12b1c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.56457439Z 53 PC: 12b29 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T23:01:45.566963269Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:01:45.568753432Z 37 PC: 12b59 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.570519391Z 37 PC: 12b61 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:01:45.572702683Z 42 PC: 12b65 | Get date 0x12b65: or al, al
0x12b67: jmp 0x12b6d
0x12b69: cmp al, 5
0x12b6b: jb 0x12b75
0x12b6d: mov ax, 0x2517
0x12b70: mov dx, 0x185
0x12b73: int 0x21
0x12b75: xor ax, ax
0x12b77: mov ds, ax
0x12b79: mov word ptr [0x467], 0x3110
0x12b7f: jmp 0x12a87
0x12b82: add byte ptr [bx + si], al
0x12b84: add byte ptr [bx + si], al
0x12b86: add byte ptr [bx + si], al
0x12b88: add byte ptr [bx + si], al
0x12b8a: add byte ptr [bx + si], al
0x12b8c: add byte ptr [bx + si], al
0x12b8e: add byte ptr [bx + si], al
0x12b90: add byte ptr [bx + si], al
0x12b92: add byte ptr [bx + si], al
2018-12-17T23:01:45.575596541Z 37 PC: 12b75 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')